Legal

Privacy Policy

This Privacy Policy explains how Orcha LLC collects, uses, discloses, and protects information in connection with the Orcha platform, our websites, our REST API, our MCP server, and related services.

Last updated: July 24, 2026

1. Who we are

Orcha is operated by Orcha LLC, a limited liability company based in Yorba Linda, California, United States. Orcha is a centralized storage platform for AI agent context files and related data. By creating an account or otherwise using the services, you agree to the practices described in this policy. If you do not agree, please do not use the services.

For any questions about this policy or your information, contact us at privacy@tryorcha.com.

2. Information we collect

We collect information you provide, information created when you use the services, and information we receive from third parties.

Information you provide includes:

  • account and authentication details received from your identity provider (Google or GitHub), such as your name, email address, profile identifier, and profile image (we never receive or store your Google or GitHub password);
  • content you store, including context files, folders, structured database records, tags, and related metadata (“Your Content”);
  • organization and workspace information such as names, slugs, roles, membership, and invitations;
  • limited billing records processed through our payment provider, such as your plan, subscription status, billing history, and a customer identifier (we do not store full payment card numbers); and
  • communications you send us, including support requests and survey responses.

Information collected automatically includes IP address, browser and device type, operating system, pages and features accessed, actions taken, timestamps, diagnostic and error data, and cookie identifiers. When you or your AI agents access the services through our API or MCP server, we log request metadata such as the token used, endpoints or tools called, timestamps, request volume, and response status.

Information from third parties includes data from the identity providers you sign in with, our payment processor, and our analytics, error-monitoring, and email providers.

3. How we use information

We use information to:

  • provide, operate, maintain, and improve the services, including storing Your Content and making it available to you and the AI agents you authorize;
  • authenticate you, manage your account, and secure access through API tokens and role-based permissions;
  • process transactions, manage subscriptions, and enforce plan and rate limits;
  • monitor, debug, and improve performance, reliability, and security, including detecting and preventing fraud, abuse, and unauthorized access;
  • respond to your requests and provide customer support;
  • send you service-related communications and, where permitted, product updates or marketing messages you can opt out of; and
  • comply with legal obligations and enforce our agreements.

We do not sell your personal information, and we do not use the contents of Your Content to train our own or third parties' machine-learning models.

4. How we share information

We share information only as described below, and we do not sell your personal information.

Service providers that perform services on our behalf, under contracts requiring them to protect the information and use it only to provide services to us, by category:

  • authentication — the identity providers you sign in with (Google, GitHub);
  • payments — our payment processor (Stripe);
  • hosting and infrastructure — the cloud and database providers that host the services;
  • analytics — providers that help us understand usage of the services;
  • error and performance monitoring — providers that help us detect and fix problems; and
  • email — providers that help us send transactional and, where applicable, marketing email.

We also share information with AI agents and integrations you authorize through API tokens or connected clients, within the scope and permissions you set; members of your organization or workspace according to configured permissions; authorities or advisers when legally required; and a successor in connection with a business transfer.

5. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember preferences, understand service performance, and protect against abuse. Browser settings may let you limit cookies, but some service features may stop working correctly.

6. Data retention

We retain your information for as long as your account is active or as needed to provide the services. When you delete Your Content, it is first moved to a trash/soft-delete state so you can recover it, and is then permanently removed on our normal deletion cycles.

When you close your account or request deletion, we delete or de-identify your personal information and Your Content within 30 days, unless you request otherwise or we are required to retain certain information longer to comply with legal obligations, resolve disputes, maintain security, or enforce our agreements (for example, limited billing records). Backup copies may persist for a limited additional period until overwritten on our normal backup rotation.

7. Security

We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, scoped API tokens with granular permissions, role-based access control, and secure session management. No method of transmission or storage is completely secure, so you should also protect your credentials and API tokens, limit their scope, and promptly report suspected unauthorized access.

8. Your choices and rights

You can access and update much of your information directly in the services. You may also:

  • access, correct, or delete your account information and Your Content in the services or by contacting us at privacy@tryorcha.com;
  • close your account at any time, after which we delete your information as described above;
  • revoke or rotate API tokens in your settings;
  • opt out of marketing email using the unsubscribe link or by contacting us (you cannot opt out of essential service and security communications while you have an account); and
  • control cookies through your browser settings.

We will respond to requests within a reasonable time and may need to verify your identity before completing a request.

9. Children

The services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us at privacy@tryorcha.com and we will delete it.

10. International users

Orcha is operated from the United States, and our service providers may process and store information in the United States and other countries. If you access the services from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

11. Governing law

This policy is governed by the laws of the State of California and the United States, without regard to conflict-of-laws principles.

12. Changes to this policy

We may update this policy as our practices or legal obligations change. We will post the updated policy and revise the date above, and we may provide additional notice for material changes when required. Your continued use of the services after an update takes effect means you accept the revised policy.